ACEN MDR Threat Alert – Tableau Server & Desktop – (CVE-2025-26496, CVSS 9.6/10)

On the 22nd of August 2025, a critical vulnerability (CVE-2025-26496, CVSS 9.6/10) was disclosed affecting Salesforce Tableau Server and Tableau Desktop across Windows and Linux platforms.

The flaw allows attackers on the same network segment to upload specially crafted files and achieve arbitrary code execution with no privileges or user interaction required. Here’s how to protect your environment and how ACEN supports affected clients.

What’s going on?

⚠️ CVE-2025-26496 is a Type Confusion vulnerability in the File Upload modules of Tableau products.

⚠️ Attackers can exploit the flaw via Local Code Inclusion, using malicious file uploads to execute arbitrary code.

⚠️ The vulnerability is exploitable from adjacent networks and can lead to complete system compromise.

Affected versions & mitigation

Product

Affected Versions

Fixed Version

Tableau Server & Desktop

Before 2025.1.3
Before 2024.2.12
Before 2023.3.19

Apply latest updates from Salesforce

Mitigation guidance:

  1. Immediately update Tableau to a secure version
  2. Segment networks to restrict adjacent access
  3. Monitor upload directories and logs
  4. Enforce least privilege on file upload modules
  5. Review installations with a security assessment

Why is this a problem?

  • This vulnerability is especially dangerous due to:
    • No authentication or user interaction required
    • Adjacent network attack vector
    • High potential for remote code execution
    • Impact on confidentiality, integrity, and availability
  • Attackers could gain access to sensitive systems, deploy malware, and maintain persistence across compromised hosts.

How does ACEN protect its customers?

If you’re using ACEN’s Extended Detection and Response (XDR) solution, it is designed to block many types of exploitation attempts that occur after the initial compromise. This enables our teams to stop threats and launch an investigation.

ACEN’s MDR service also deploys tailored detection scenarios that monitor system logs from Windows, firewalls, Microsoft 365, and other sources to identify and stop threat actors.

In the event of a serious incident, our Computer Security Incident Response Team (CSIRT) is available to provide expert support and guidance.

We continue to emphasize the importance of proactive security measures. Please ensure your systems are updated with the latest patches and configurations.

What can you do to mitigate the attack?

✅ Apply the latest Tableau patches immediately
✅ Review upload permissions and logs
✅ Isolate Tableau environments from high-risk network segments
✅ Audit your Tableau deployments for misconfigurations or legacy versions

But what if you can’t?

🛡️ Restrict access to the upload functionality via firewall and access control
🛡️ Monitor for suspicious file upload activity
🛡️ Temporarily disable external upload functions if possible

Need help to mitigate the risks?

Get in contact with Ken Van Hasselt today!

Share this article

Interested in learning more about our solutions and how they can benefit your business?

Contact us now for personalized insights and solutions.

Related articles

ACEN MDR - Overview image

Press release – ACEN announces full integration of Nynox into new ACEN MDR division

ACEN has fully integrated Nynox under the new ACEN Managed Detection & Response (MDR)...
Acen - website banner - 1920 x 320

Phishing prevention is key for cyber resilience: ACEN and OutKept join forces

Phishing remains one of the most common entry points for attackers and hackers. To...

Overview image for insight about ACEN MDR: a new chapter

ACEN MDR: A new chapter in Managed Detection & Response

As you know, cybersecurity never stands still and neither do we. Nynox is now...

Subscribe to our newsletter

We only use your e-mail address to send newsletters.

We do not pass on your address to third parties.

Security as a Service

Experience peace of mind with our Security as a Service – your company’s ultimate shield against threats, featuring reliable 24/7 protection, local support, and a tailored approach to meet all your unique security needs.

We are looking for talent

Check out our careers platform and discover our wide range of cybersecurity opportunities!

ACEN logo with orange swirl
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.